This detection rule identifies adversary behavior involving the deployment of a malicious web shell named “EFSO_2.asp,” which attackers often use to establish persistent access and execute commands on compromised web servers. A SOC team should proactively hunt for this artifact in Azure Sentinel because web shells serve as critical footholds that enable lateral movement, data exfiltration, and remote command execution across the organization’s web infrastructure.
rule webshell_asp_EFSO_2 {
meta:
description = "Web Shell - file EFSO_2.asp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "a341270f9ebd01320a7490c12cb2e64c"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "%8@#@&P~,P,PP,MV~4BP^~,NS~m~PXc3,_PWbSPU W~~[u3Fffs~/%@#@&~~,PP~~,M!PmS,4S,mBPNB"
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file EFSO_2.asp detection rule, including suggested filters and exclusions:
Scheduled Backup Utility Execution
EFSO_2.asp to the IIS root directory (C:\inetpub\wwwroot) to verify disk space and service health before archiving logs.vbruntime.exe (Veeam) or commvault.exe, specifically when the file path contains \wwwroot\EFSO_2.asp and the user context is a dedicated service account like DOMAIN\svc_backup.Automated Patch Management Deployment
EFSO_2.asp) to confirm that the web server is responsive and the patch applied successfully.ProcessName matches ccmexec.exe or wuauserv.exe, and the file hash of EFSO_2.asp matches a known “golden” hash stored in your asset inventory database.Third-Party Monitoring Agent Initialization
EFSO_2.asp to establish connectivity and report initial metrics to the central dashboard.